Legal

Privacy Policy

This Privacy Policy explains how Orcha LLC collects, uses, discloses, and protects information in connection with the Orcha platform, our websites, our REST API, our MCP server, and related services.

Last updated: August 7, 2026

1. Who we are

Orcha is operated by Orcha LLC, a limited liability company based in Yorba Linda, California, United States. Orcha is a centralized storage platform for AI agent context files and related data. By creating an account or otherwise using the services, you agree to the practices described in this policy. If you do not agree, please do not use the services.

For any questions about this policy or your information, contact us at privacy@tryorcha.com.

2. Information we collect

We collect information you provide, information created when you use the services, and information we receive from third parties.

Information you provide includes:

  • account and authentication details received from your identity provider (Google or GitHub), such as your name, email address, profile identifier, and profile image (we never receive or store your Google or GitHub password);
  • content you store, including context files, folders, structured database records, tags, and related metadata (“Your Content”);
  • organization and workspace information such as names, slugs, roles, membership, and invitations;
  • limited billing records processed through our payment provider, such as your plan, subscription status, billing history, and a customer identifier (we do not store full payment card numbers); and
  • communications you send us, including support requests and survey responses.

Information collected automatically includes IP address, browser and device type, operating system, pages and features accessed, actions taken, timestamps, diagnostic and error data, and cookie identifiers. When you or your AI agents access the services through our API or MCP server, we log request metadata such as the token used, endpoints or tools called, timestamps, request volume, and response status.

Information from third parties includes data from the identity providers you sign in with, our payment processor, our analytics, error-monitoring, and email providers, and content and metadata from the third-party sources you choose to connect, as described in the Connected sources and Google user data section below.

3. How we use information

We use information to:

  • provide, operate, maintain, and improve the services, including storing Your Content and making it available to you and the AI agents you authorize;
  • authenticate you, manage your account, and secure access through API tokens and role-based permissions;
  • process transactions, manage subscriptions, and enforce plan and rate limits;
  • monitor, debug, and improve performance, reliability, and security, including detecting and preventing fraud, abuse, and unauthorized access;
  • respond to your requests and provide customer support;
  • send you service-related communications and, where permitted, product updates or marketing messages you can opt out of; and
  • comply with legal obligations and enforce our agreements.

We do not sell your personal information, and we do not use the contents of Your Content or of content synced from your connected sources to train our own or third parties' machine-learning models.

4. Connected sources and Google user data

You can connect third-party sources (for example GitHub, Notion, Google Drive, or Gmail) so that Orcha can index selected content and make it retrievable by you and the AI agents you authorize. Connected sources are read-only: we request only read scopes, and Orcha never modifies, sends, or deletes anything in the connected service.

Google user data. When you connect a Google source, we access only the data covered by the read-only scopes you approve, such as Drive file and folder metadata, the contents of the Google Docs, Sheets, and Slides files you choose to index, and, if you connect Gmail, messages in the labels you select. We use this data solely to build your searchable index and to return your own content to you and the agents you authorize, with citations back to the original item. OAuth tokens are stored encrypted, and indexed content is protected with the same measures described in the Security section.

With respect to Google user data, we:

  • do not transfer it to third parties except as necessary to provide and secure the services (for example, our hosting providers), to comply with applicable law, or as part of a business transfer as described in this policy;
  • do not use it for advertising;
  • do not allow humans to read it, except with your affirmative agreement, where necessary for security purposes such as investigating abuse, or to comply with applicable law; and
  • do not use it, and do not allow any third party to use it, to develop, improve, or train generalized artificial intelligence or machine-learning models; search indexes and embeddings derived from your data exist only to return your own content to you.

Orcha's use and transfer of information received from Google APIs to any other app will adhere to Google API Services User Data Policy, including the Limited Use requirements.

You can disconnect a source at any time in your connector settings, or revoke Orcha's access from your Google Account security settings. Disconnecting stops all further access, and we delete the stored tokens and the content synced from that source on our normal deletion cycles. Closing your account removes connected-source data as described in the Data retention section.

5. How we share information

We share information only as described below, and we do not sell your personal information.

Service providers that perform services on our behalf, under contracts requiring them to protect the information and use it only to provide services to us, by category:

  • authentication — the identity providers you sign in with (Google, GitHub);
  • payments — our payment processor (Stripe);
  • hosting and infrastructure — the cloud and database providers that host the services;
  • analytics — providers that help us understand usage of the services;
  • error and performance monitoring — providers that help us detect and fix problems; and
  • email — providers that help us send transactional and, where applicable, marketing email.

We also share information with AI agents and integrations you authorize through API tokens or connected clients, within the scope and permissions you set; members of your organization or workspace according to configured permissions; authorities or advisers when legally required; and a successor in connection with a business transfer.

6. Cookies and similar technologies

We use cookies and similar technologies to keep you signed in, remember preferences, understand service performance, and protect against abuse. Browser settings may let you limit cookies, but some service features may stop working correctly.

7. Data retention

We retain your information for as long as your account is active or as needed to provide the services. When you delete Your Content, it is first moved to a trash/soft-delete state so you can recover it, and is then permanently removed on our normal deletion cycles.

When you close your account or request deletion, we delete or de-identify your personal information and Your Content within 30 days, unless you request otherwise or we are required to retain certain information longer to comply with legal obligations, resolve disputes, maintain security, or enforce our agreements (for example, limited billing records). Backup copies may persist for a limited additional period until overwritten on our normal backup rotation.

8. Security

We use technical and organizational measures designed to protect your information, including encryption in transit, access controls, scoped API tokens with granular permissions, role-based access control, and secure session management. No method of transmission or storage is completely secure, so you should also protect your credentials and API tokens, limit their scope, and promptly report suspected unauthorized access.

9. Your choices and rights

You can access and update much of your information directly in the services. You may also:

  • access, correct, or delete your account information and Your Content in the services or by contacting us at privacy@tryorcha.com;
  • close your account at any time, after which we delete your information as described above;
  • revoke or rotate API tokens in your settings;
  • disconnect connected sources at any time in your settings, which stops further syncing and removes the content synced from them;
  • opt out of marketing email using the unsubscribe link or by contacting us (you cannot opt out of essential service and security communications while you have an account); and
  • control cookies through your browser settings.

We will respond to requests within a reasonable time and may need to verify your identity before completing a request.

10. Children

The services are not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us personal information, contact us at privacy@tryorcha.com and we will delete it.

11. International users

Orcha is operated from the United States, and our service providers may process and store information in the United States and other countries. If you access the services from outside the United States, your information will be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your country.

12. Governing law

This policy is governed by the laws of the State of California and the United States, without regard to conflict-of-laws principles.

13. Changes to this policy

We may update this policy as our practices or legal obligations change. We will post the updated policy and revise the date above, and we may provide additional notice for material changes when required. Your continued use of the services after an update takes effect means you accept the revised policy.